{"cvss":7.2,"datePublished":"2023-02-10","dateUpdated":"2023-02-10","description":"Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.","dueDate":"2023-03-03","id":"CVE-2023-0669","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://my.goanywhere.com/webclient/DownloadProductFiles.xhtml. Fortra users must have an account in order to login and access the patch.;  https://nvd.nist.gov/vuln/detail/CVE-2023-0669","product":"GoAnywhere MFT","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"Fortra GoAnywhere MFT Remote Code Execution Vulnerability","vendor":"Fortra"}